5 ms·
I have indeed found that it's difficult to silo access to specific resources with AWS IAM. I use these custom policies a lot, which give write access to a spec
by jackconsidine 4y ago
I have indeed found that it's difficult to silo access to specific resources with AWS IAM.
I use these custom policies a lot, which give write access to a specific S3 Bucket [0], and give sending capabilities for a specific SES Identity [1] respectively:
[0]https://koptional.notion.site/IAM-Policy-for-select-S3-Access-on-a-single-bucket-1d368c7eb45446b1bd653d1a0425042c https://koptional.notion.site/IAM-Policy-for-select-S3-Acces...
[1] https://koptional.notion.site/IAM-Policy-for-email-sending-on-behalf-of-single-SES-identity-414f02acd0e4496eb994e171a74f3fdf https://koptional.notion.site/IAM-Policy-for-email-sending-o...
- simonw 4y agoI ended up writing a whole custom tool for generating credentials and policies for specific S3 buckets: - https://s3-credentials.readthedocs.io/ https://s3-credentials.readthedocs.io/ - https://simonwillison.net/2021/Nov/3/s3-credentials/ https://simonwillison.net/2021/Nov/3/s3-credentials/ - https://simonwillison.net/2022/Jan/18/weeknotes/ https://simonwillison.net/2022/Jan/18/weeknotes/
- jackconsidine 4y agoWhoa this is awesome! Wish I knew about this. It's really polished